VYPR
Medium severity4.3NVD Advisory· Published Jun 20, 2025· Updated Apr 23, 2026

CVE-2025-49973

CVE-2025-49973

Description

Missing authorization in GrandPlugins Image Sizes Controller plugin (≤1.0.10) allows unauthenticated exploitation of access controls.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in GrandPlugins Image Sizes Controller plugin (≤1.0.10) allows unauthenticated exploitation of access controls.

Vulnerability

Overview CVE-2025-49973 is a missing authorization vulnerability in the GrandPlugins Image Sizes Controller WordPress plugin (and its Create Custom Image Sizes / Disable Image Sizes variant). The plugin fails to properly verify access control security levels in certain functions, effectively missing required authorization, authentication, or nonce checks [1]. This class of flaw affects versions through 1.0.10.

Attack

Vector An attacker can exploit this vulnerability by sending crafted requests to the affected plugin endpoints without needing any prior authentication or elevated privileges. Because the plugin lacks proper access control checks, unauthenticated users are able to trigger actions that should be restricted to higher-privileged roles [1]. The vulnerability is considered easy to exploit and is used in mass-exploit campaigns targeting thousands of websites simultaneously.

Impact

Successful exploitation allows an unauthenticated attacker to perform unauthorized actions that result in exploitation of incorrectly configured access control security levels. This could lead to unintended modification of image size settings or other capabilities normally reserved for administrative users, potentially compromising site configuration.

Mitigation

The vulnerability has been addressed in a later version (past 1.0.10). Users are strongly advised to update the plugin immediately to the latest available version [1]. If unable to update, site administrators should seek assistance from their hosting provider or web developer.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.